ISO/IEC 27001
Consultants are qualified to perform ISO 27001 audits, gap analysis and certification support. We do not sell a binder of policies. We help you build an information security management system that matches how the organisation actually works — then produce the evidence a certification body will accept.
Where the control set is the actual requirement, we work to ISO/IEC 27002, and to ISO/IEC 27701 when privacy management sits beside the ISMS.
NIS2
The EU Network and Information Security Directive (NIS2) raises the bar for essential and important entities, and for their suppliers. We map current technical and organisational measures against the directive, identify gaps, and help you close them — including the incident-reporting and supply-chain duties that catch teams off guard.
UK organisations selling into the EU, and Portuguese operations in scope, are a typical fit.
NIST CSF 2.0 and the 800-series
For organisations that need to speak NIST — Cybersecurity Framework 2.0, SP 800-53, SP 800-171 — we translate the control families into tests, architecture changes and evidence, rather than a spreadsheet of 'partially implemented'.
Other regimes we cover
UK Cyber Essentials and Cyber Essentials Plus — the baseline many insurers and public-sector buyers now expect.
IEC 62443 for industrial control and OT. We already research SCADA and ICS software; the standard work sits on that technical base.
SOC 2 for product companies selling into the US. PCI DSS where card data is in scope.
Why a technical firm
Most gap analyses are written by people who have never exploited a real system. Ours are not. The same consultants who find 0-days can tell you whether a control would actually stop an attacker — and what to put in its place if it would not.
